{"id":"MGASA-2026-0388","summary":"Updated thunderbird packages fix security vulnerabilities","details":"Uninitialized memory in MIME parsing. (CVE-2026-84639)\nOne byte overflow read in mail parser. (CVE-2026-84640)\nInformation disclosure due to malicious IMAP server response.\n(CVE-2026-84641)\nCalendar invitation attachments could launch local executables.\n(CVE-2026-84637)\nAllowed UNC hostnames for attachments interpreted as a regular\nexpression. (CVE-2026-84642)\nSandbox escape in the Remote Settings Client component. (CVE-2026-75874)\nPrivilege escalation in the DOM: Workers component. (CVE-2026-16365)\nUse-after-free in the JavaScript: GC component. (CVE-2026-84118)\nSandbox escape due to use-after-free in the DOM: Navigation component.\n(CVE-2026-84119)\nUse-after-free in the Audio/Video component. (CVE-2026-84120)\nSandbox escape due to use-after-free in the DOM: Security component.\n(CVE-2026-84121)\nUse-after-free in the Audio/Video component. (CVE-2026-84122)\nPrivilege escalation due to use-after-free in the Graphics: WebGPU\ncomponent. (CVE-2026-84123)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84124)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84125)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-16371)\nPrivilege escalation in the Application Update component.\n(CVE-2026-74952)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84129)\nInformation disclosure in the Graphics: WebGPU component.\n(CVE-2026-84130)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-84131)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-84132)\nSite isolation issue in the DOM: Push Subscriptions component.\n(CVE-2026-84133)\nOther issue in the Profile Backup component. (CVE-2026-84134)\nOther issue in the DOM: Navigation component. (CVE-2026-84136)\nSpoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)\nClickjacking issue in the DOM: Events component. (CVE-2026-84139)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84140)\nInteger overflow in the Graphics: ImageLib component. (CVE-2026-84141)\nInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2\nand Thunderbird ESR 140.15. (CVE-2026-84143)\nInternally found bugs fixed in Thunderbird 155 and Thunderbird ESR\n153.2. (CVE-2026-84144)\nInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2\nand Thunderbird ESR 140.15. (CVE-2026-84145)\n","modified":"2026-09-09T18:27:30.091170190Z","published":"2026-09-09T18:01:33Z","upstream":["CVE-2026-16365","CVE-2026-16371","CVE-2026-74952","CVE-2026-75874","CVE-2026-84118","CVE-2026-84119","CVE-2026-84120","CVE-2026-84121","CVE-2026-84122","CVE-2026-84123","CVE-2026-84124","CVE-2026-84125","CVE-2026-84129","CVE-2026-84130","CVE-2026-84131","CVE-2026-84132","CVE-2026-84133","CVE-2026-84134","CVE-2026-84136","CVE-2026-84137","CVE-2026-84139","CVE-2026-84140","CVE-2026-84141","CVE-2026-84143","CVE-2026-84144","CVE-2026-84145","CVE-2026-84637","CVE-2026-84639","CVE-2026-84640","CVE-2026-84641","CVE-2026-84642"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0388.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36245"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/140.14.1esr/releasenotes/"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/153.1.1esr/releasenotes/"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/140.15.0esr/releasenotes/"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/153.2.0esr/releasenotes/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0388.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0388.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.15.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0388.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.15.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0388.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}